CVE-2021-46239Use After Free in Gpac

CWE-416Use After Free4 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.3%
top 49.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 21
Latest updateJan 22

Description

The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at utils/alloc.c. This vulnerability can lead to a Denial of Service (DoS).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDgpac/gpac1.1.0
debiandebian/gpac

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m2jp-6q38-p4fm: The binary MP4Box in GPAC v12022-01-22
OSV
CVE-2021-46239: The binary MP4Box in GPAC v12022-01-21

📋Vendor Advisories

1
Debian
CVE-2021-46239: gpac - The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulne...2021
CVE-2021-46239 — Use After Free in Gpac | cvebase